浏览代码

configure ciphers for rabbitmq with enabled ssl

Moritz Kobel 7 年之前
父节点
当前提交
aa2ce72a82
共有 1 个文件被更改,包括 2 次插入0 次删除
  1. 2 0
      templates/rabbitmq.config.j2

+ 2 - 0
templates/rabbitmq.config.j2

@@ -6,6 +6,8 @@
                    {certfile,"{{ rabbitmq_config_path }}/ssl/cert.pem"},
                    {keyfile,"{{ rabbitmq_config_path }}/ssl/key.pem"},
                    {verify,verify_peer},
+                   {versions, ['tlsv1.2']},
+                   {ciphers,  [{rsa,aes_256_cbc,sha256}]},
                    {fail_if_no_peer_cert,true}]}
     {% else %}
     {tcp_listeners, [{{ rabbitmq_port }}]}